This Full time on site position offers great opportunities for career growth. Accenture Security helps organizations prepare, protect, detect, respond, and recover across all aspects of the security lifecycle. Cybersecurity challenges are different for every business and industry. Leveraging our global resources and advanced technologies, we create integrated solutions tailored to our clients' needs across their entire value chain. Whether defending against known cyberattacks, detecting and responding to unknown threats, or running an entire security operations center, we help companies build cyber resilience and grow with confidence. We combine risk strategy, digital identity, cyber defense, application security, and managed services to rethink the entire security lifecycle. We are seeking an Azure Cloud Infrastructure Security Engineer to join our Porto Cybersecurity CoE team. This role is based in Lisbon and will support the design, implementation and secure operation of Azure landing zones and the IaaS and PaaS services deployed within them. You will work directly with cloud platform, infrastructure, networking and DevOps teams to implement cloud security controls, configure platform guardrails and validate the secure deployment of Azure resources. The role combines practical Azure infrastructure knowledge with cloud security expertise. Key areas include identity and access management, network security, platform hardening, Azure Policy, encryption, logging and monitoring, secure resource configuration and infrastructure-as-code security. You will participate in cloud security initiatives across the organization, working closely with business, infrastructure, engineering and DevOps teams to strengthen the security posture of Azure-based solutions and promote security best practices across cloud environments.
Qualifications
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Engineering, or a related field, or equivalent professional experience
- Minimum of 1 years of experience in Azure Cloud engineering and cloud security, infrastructure, or related technical roles
- Hands-on experience deploying, configuring or supporting Azure IaaS and PaaS resources
- Working knowledge of Azure landing-zone concepts, including management groups, subscriptions, resource organization, policy and access control
- Practical understanding of Azure networking, including virtual networks, subnets, routing, network security groups, firewalls, private connectivity and DNS
- Understanding of Azure identity and access management, including role-based access control, managed identities and least-privilege access
- Experience implementing or validating cloud security baselines and resource hardening requirements
- Familiarity with Azure Policy and policy-driven cloud governance
- Basic experience with Terraform, Bicep, ARM templates or another infrastructure-as-code technology
- Understanding of encryption, key management, secrets management, logging and monitoring in Azure
- Ability to analyse cloud configurations, identify security weaknesses and support their remediation
- Understanding of cloud security principles, risk assessment methodologies, and security control validation
- Knowledge of cloud compliance, risk assessment, and security governance concepts
- Familiarity with cloud security posture management (CSPM) solutions
- Basic understanding of CI/CD processes and associated security considerations
- Strong analytical, problem-solving, and communication skills
- Ability to collaborate effectively with cloud platform, networking, infrastructure and DevOps engineers
- Fluent English, with clear written and verbal communication skills
Responsibilities
- Support business and technology projects by providing cloud security expertise throughout the project lifecycle
- Support the secure design, implementation and continuous improvement of Azure landing zones
- Implement and validate security controls for Azure IaaS and PaaS resources
- Define, maintain and promote baselines and hardening standards to Azure subscriptions, virtual machines, storage, databases, application services and other cloud resources
- Support the implementation of Azure identity and access controls, including role-based access control, managed identities, privileged access and least-privilege permissions
- Implement and troubleshoot network security controls, including network security groups, Azure Firewall, private endpoints, service endpoints, routing and network segmentation
- Review cloud architectures and validate security requirements through security assessments and architecture reviews
- Contribute to the design, implementation and continuous improvement of secure Azure cloud architectures
- Assess cloud-native services and workloads to identify security risks and recommend mitigation measures
- Secure CI/CD pipelines by defining and promoting security controls across development, building, testing and deployment processes
- Collaborate with infrastructure, development and DevOps teams to integrate security controls into cloud environments
- Monitor cloud security posture and support remediation activities identified through CSPM findings
- Assist in the enforcement of cloud governance and security policies across Azure environments
- Configure and maintain Azure Policies to implement and enforce cloud security controls
- Stay informed about emerging cloud security threats, vulnerabilities and industry best practices
Nice to Have
- Experience supporting or implementing an Azure landing zone and network security components
- Hands-on experience with Azure Policy and CSPM tools
- Experience securing Azure virtual machines, storage accounts, databases, application services, containers or Kubernetes services
- Experience performing cloud security assessments and secure cloud architecture reviews
- Exposure to security baseline development and cloud hardening practices
- Understanding of cloud risk management and remediation processes
- Knowledge of CI/CD security controls and secure deployment practices
Relevant Azure, cloud, or cybersecurity certifications are considered an advantage, including:
- Microsoft Certified: Azure Fundamentals (AZ-900)
- Microsoft Certified: Azure Administrator Associate (AZ-104)
- Microsoft Certified: Azure Security Engineer Associate (AZ-500)
Additional Information
Location: Lisbon (hybrid). Minimum of 3 days per week onsite in Alfragide. Travel: Flexibility to travel within Europe for project activities and stakeholder engagements